Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.
2017-12-11T21:29:00.517
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nodejs | node.js | ≤ 4.1.2 | Yes |
Application | nodejs | node.js | < 4.8.7 | Yes |
Application | nodejs | node.js | ≤ 6.8.1 | Yes |
Application | nodejs | node.js | < 6.12.2 | Yes |
Application | nodejs | node.js | ≤ 8.8.1 | Yes |
Application | nodejs | node.js | < 8.9.3 | Yes |
Application | nodejs | node.js | < 9.2.1 | Yes |